Impact
An incorrect access control check in the updateSlaveIpList function of TOTOLINK T6 firmware 4.1.5cu.748_B20211015 lets an unauthenticated attacker overwrite the slave IP inventory state by sending a crafted MQTT message to the cs_broker component. The flaw permits unauthorized modification of the device’s IP configuration, which can undermine the intended network settings. The impact is focused on configuration alteration, granting the attacker control over how the device communicates with other devices or networks.
Affected Systems
TOTOLINK T6 devices running firmware version 4.1.5cu.748_B20211015 are affected. No other firmware versions or other TOTOLINK products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a high‑severity vulnerability. Although the EPSS score is reported as < 1 %, the likelihood of exploitation remains low. The flaw can be leveraged by sending a custom MQTT message to the cs_broker component; if the MQTT port is reachable, no authentication is required, allowing unauthenticated remote attackers to alter configuration. This vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment